CVE-2025-67813
Unknown Unknown - Not Provided
Insecure Permissions on Named Pipes in Quest KACE Desktop Authority

Publication date: 2026-01-12

Last updated on: 2026-01-12

Assigner: MITRE

Description
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-12
Last Modified
2026-01-12
Generated
2026-06-16
AI Q&A
2026-01-13
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
quest kace_desktop_authority to 11.3.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-67813 is a security vulnerability in Quest KACE Desktop Authority versions up to 11.3.1 where the Named Pipes used for inter-process communication have insecure permissions. This means that these Named Pipes were created without proper access control restrictions, allowing unauthorized local users to access them. This flaw could allow unintended interactions or privilege escalation within the application. [2]

Impact Analysis

This vulnerability can impact you by allowing unauthorized local users to access the Named Pipes used by the application, potentially leading to privilege escalation or unintended interactions within the application context. This could compromise the security and integrity of the system where Quest KACE Desktop Authority is installed. [2]

Detection Guidance

This vulnerability can be detected by checking the permissions on the Named Pipes used by Quest KACE Desktop Authority up to version 11.3.1. Since the issue involves insecure permissions allowing unauthorized local access, you can inspect the Named Pipes permissions on the affected system. Specific commands are not provided in the resources, but generally, on Windows systems, you can use PowerShell or Sysinternals tools like 'AccessChk' to review Named Pipe permissions. [2]

Mitigation Strategies

The immediate step to mitigate this vulnerability is to upgrade Quest KACE Desktop Authority to version 11.3.2 or later, as this version contains the patch that fixes the insecure Named Pipe permissions issue. [2]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-67813. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart